Impact
An authenticated low‑privileged user can exploit incomplete input validation and improperly configured folder permissions to execute arbitrary code within Idira Privileged Session Manager (PSM). This flaw, classified as CWE‑22, can compromise system integrity and confidentiality.
Affected Systems
The vulnerability affects CyberArk Software’s Privileged Session Manager, also known as PSM Vault, in all releases before 15.0.3, 14.6.3, 14.2.5, and 14.0.5. Systems running any of these affected versions should be considered vulnerable until updated.
Risk and Exploitability
The CVSS v3 score is 9.3, indicating critical severity. EPSS is not available and the issue is not listed in the CISA KEV catalog. An attacker would need valid credentials with low‑privilege but authenticated access to the PSM instance, after which the vulnerability can be triggered via crafted input to grant code‑execution capabilities.
OpenCVE Enrichment